CVE-2025-30261 — Allocation of Resources Without Limits or Throttling in Systems INC Qsync Central
Severity
7.1HIGHNVD
EPSS
0.2%
top 63.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 29
Description
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource.
We have already fixed the vulnerability in the following version:
Qsync Central 5.0.0.0 ( 2025/06/13 ) and later
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Packages2 packages
🔴Vulnerability Details
2📋Vendor Advisories
1Microsoft▶
Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect↗2024-04-09